CVE-2025-40800
published 2025-12-09CVE-2025-40800: A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX…
PriorityP349high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.19%
8.6th percentile
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | comos_v10.6 | < V10.6.1 | V10.6.1 |
| siemens | nx_v2412 | < V2412.8700 | V2412.8700 |
| siemens | nx_v2506 | < V2506.6000 | V2506.6000 |
| siemens | simcenter_3d | < V2506.6000 | V2506.6000 |
| siemens | simcenter_femap | < V2506.0002 | V2506.0002 |
| siemens | solid_edge_se2025 | < V225.0 Update 10 | V225.0 Update 10 |
| siemens | solid_edge_se2026 | < V226.0 Update 1 | V226.0 Update 1 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.09.1CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xg9v-jc69-p54f: A vulnerability has been identified in COMOS V10
ghsa_unreviewed·2025-12-09
CVE-2025-40800 [CRITICAL] CWE-295 GHSA-xg9v-jc69-p54f: A vulnerability has been identified in COMOS V10
A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.
CISA ICS
Siemens COMOS
cisa_ics·2026-02-12·CVSS 3.4
[LOW] Siemens COMOS
ICS Advisory
##
Siemens COMOS
Release DateFebruary 12, 2026
Alert CodeICSA-26-043-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
COMOS is affected by multiple vulnerabilities that could allow an attacker to execute arbitrary code or cause denial of service condition, data infiltration or perform access control violations. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens COMOS are affected:
- COMOS V10.4 vers:intdot/<10.4.5, vers:intdot/<10.4.5 (CVE-2024-47875, CVE-2025-278
CISA ICS
Siemens IAM Client
cisa_ics·2025-12-11·CVSS 7.4
[HIGH] Siemens IAM Client
ICS Advisory
##
Siemens IAM Client
Release DateDecember 11, 2025
Alert CodeICSA-25-345-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: IAM Client
- Vulnerability: Improper Certificate Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated
No detection rules found.
No public exploits indexed.
2025-12-09
Published